Gotta fly: Lazarus targets the UAV sector
Essential information
- Published
- 23/10/2025 13:51
- Modified
- 24/10/2025 11:42
- Tags
- 2025-10-23 operation dreamjob quanpinloader scoringmathtea
- Related entities
- 1 intrusion sets (apt), 14 techniques (mitre), 3 malware, 5 others
Description
ESET researchers have uncovered a new instance of Operation DreamJob, a campaign attributed to the North Korea-aligned Lazarus group, targeting European defense companies involved in UAV technology. The attacks align with North Korea's efforts to enhance its drone program, likely aiming to steal proprietary information and manufacturing know-how. The campaign uses social engineering tactics, trojanized open-source projects, and deploys the ScoringMathTea RAT. The attackers' toolset includes various droppers, loaders, and downloaders, with a focus on UAV-related targets. This activity highlights the ongoing threat posed by Lazarus and North Korea's interest in advancing its drone capabilities through cyberespionage.